Skip to main content
DTI

INDUSTRY · BANKING & FSI

Banking cybersecurity — phishing-resistant authentication, PSrE e-signatures, and strong audit trails.

DTI helps banks and financial institutions meet OJK & BI expectations — FIDO2 hardware MFA for critical access, PSrE-certified e-signatures for customer documents, conglomerate reporting, and certified data destruction.

REGULATORY LANDSCAPE

Compliance is a license condition.

Indonesian banks operate under the dual oversight of Otoritas Jasa Keuangan (OJK) and Bank Indonesia (BI). OJK governs prudential supervision, IT risk management, and consumer protection. BI governs payment systems, monetary stability, and the national payment ecosystem.

Specific rules accumulate. POJK 11/2022 mandates IT risk management for commercial banks. BI Regulation 2/2024 sets information system security and cyber resilience requirements for payment system organizers. Digital signatures must be PSrE-standard under KOMDIGI Regulation 11/2018. Payment systems must integrate with BI-RTGS, GPN, and BI-FAST.

Layer on top: UU PDP (Law 27/2022) for customer data protection, BSSN cyber incident reporting requirements, and OJK's risk-based authentication expectations. Every system, every vendor, every integration must defend in regulatory inspection — not just at go-live, but over the lifetime of the deployment.

BANKING & FSI CHALLENGES

Where teams in this industry need depth

Four areas where Banking & FSI teams most often need specialist technology that meets regulator expectations without disrupting operations.

CHALLENGE

Wet signatures slowing onboarding

Customer onboarding, loan agreements, and account opening still rely on physical signatures across hundreds of branches. Document processing takes days, costs scale linearly with volume, and audit trails are inconsistent.

SOLVED BY
Tilaka Digital Signature
CHALLENGE

Phishing & account takeover

SMS OTP and software-based authentication remain vulnerable to phishing, SIM swap, and social engineering. Internal access to core banking and treasury operations needs phishing-resistant authentication.

SOLVED BY
YubiKey Security Key
CHALLENGE

Identity verification at scale

KYC and identity verification across millions of customer interactions strain manual processes. Banks need biometric verification with Dukcapil integration that scales without compromising assurance.

SOLVED BY
Tilaka Identity Stack
CHALLENGE

Compliance audit surface

POJK 11/2022, BI Reg. 2/2024, KOMDIGI 11/2018, UU PDP — every system, vendor, and integration must defend in regulatory inspection. Multi-vendor sprawl multiplies audit burden.

SOLVED BY
Single accountable partner

TRUSTED BY · BANKING & FSI

Financial institutions using DTI solutions

Bank BRI
Uses Tilaka
Bank BNI
Uses Data Sanitization & YubiKey
Bank BTN
Uses Data Sanitization & YubiKey
BNI Finance
Uses Tilaka

Including a major Indonesian financial conglomerate running the PIKK reporting platform — named reference available under NDA.

BANKING COMPLIANCE

Credentials that matter to your auditor

Our partner technologies hold the certifications that defend in OJK and BI inspection.

PSrE Komdigi
Tilaka Licensed · NSK No. 423/2021
FIDO2 / FIPS
Yubico Preferred Partner
ISO 27001:2013
DTI Certified InfoSec
UU PDP
Law No. 27/2022 Compliant

FAQ

Frequently asked questions

What IT security obligations does POJK 11/2022 place on Indonesian banks?

POJK No. 11/POJK.03/2022 on Information Technology Administration by Commercial Banks requires banks to implement IT risk management, data security controls, and regular cyber-resilience testing. This includes adequate authentication controls for core systems and electronic document approval. DTI supports these requirements through phishing-resistant authentication (YubiKey) and certified digital signatures (Tilaka), though compliance responsibility remains with the bank as the OJK-supervised entity.

Are Indonesian banks required to use FIDO2 hardware security keys?

No regulation mandates a specific token type; POJK 11/2022 sets a risk-based, layered-authentication principle rather than prescribing hardware. FIDO2/FIPS-certified hardware security keys are recognized industry-wide as phishing-resistant, which is why banks commonly deploy them for administrator accounts and other high-risk access. DTI supplies YubiKey as Yubico’s preferred partner for this purpose.

Is a digital signature legally valid for customer onboarding and e-KYC?

Yes. The ITE Law (Law No. 19/2016 amending Law No. 11/2008) and Government Regulation 71/2019 recognize electronic signatures, with full evidentiary weight when the signature is a certified Electronic Signature (TTE) issued by a licensed Electronic Certification Authority (PSrE). Tilaka, a KOMDIGI-licensed PSrE (NSK 423/2021), issues certified electronic signatures that integrate into bank onboarding and e-KYC workflows.

How should a bank handle customer data on storage devices being retired?

Indonesia’s Personal Data Protection Law (Law No. 27/2022) requires data controllers to secure personal data throughout its lifecycle, including when storage media is decommissioned or replaced. Standard file deletion does not permanently erase data and leaves it recoverable; standards such as NIST SP 800-88 call for clear, purge, or destroy methods matched to media type. DTI’s Data Sanitization service provides degaussing for magnetic media (HDD) and physical destruction for media that cannot be degaussed, such as SSDs.

What is a PSrE and why does it matter when choosing a digital signature vendor?

A PSrE (Electronic Certification Authority) is a party regulated under Government Regulation 71/2019 that must be registered and licensed by KOMDIGI to issue the electronic certificates underlying certified digital signatures. A vendor without PSrE licensing can only produce uncertified electronic signatures, which carry weaker legal evidentiary standing. Tilaka operates as a KOMDIGI-licensed PSrE (NSK 423/2021), giving banks a clear legal basis for their signature workflows.

READY TO MODERNIZE?

Your Banking & FSI operation deserves specialist technology.

Schedule a 30-minute consultation. We'll review your regulatory landscape, existing systems, and integration requirements — and architect a solution that fits.

Chat via WhatsApp